Twitchin Kitten - conversation community
Board Home | Search | Member List | Calendar | Help | Bank & Shopping | Lottery | Contact |

Hello There, Guest! Login Register
Login
Username:
Password: Lost Password?
 

Who loves ya Baby?

Twitchin Kitten - conversation community › The Club House › Nerdville v
« Previous 1 2 3 4 5 6 7 8 Next »

Ouch.... Someone bit the Penguin

Thread Modes
Ouch.... Someone bit the Penguin
Twitchin Kitten Offline
Omnipotent
*******
Administrators
Posts: 21,216
Threads: 2,277
Joined: Aug 2009
Reputation: 596
Mood: Bored
Share
Country: United States
Thanks Given125
Thanks Received33
  Favorite Quote: "Let's face it, this is not the worst thing you caught me doing." ~ Tony Stark / Ironman
  My Attitude: Punchy

Simoleans: §3,275,514.72
Items: (View All Items)
#1
06-14-2010, 04:53 PM
0
Linux infection proves Windows malware monopoly is over; Gentoo ships backdoor? [updated] <-- clicky for full story

Update 12:30PM PDT 14-Jun-2010: It’s much worse than it appears. According to this report, the malware-compromised code was included in the official Gentoo distribution:

Would you consider it to be a big deal if it was found in a distribution? Gentoo just released an update to remove the backdoor.

http://packages.gentoo.org/package/net-irc/unrealircd

I’m sure there will be others, I believe the package is also available in Arch. I haven’t really looked to see if it was anywhere else.

The Gentoo bug report (warning: Gentoo’s certificate does not resolve to a trusted Certifying Authority) reports that it is VERIFIED and CLOSED with this comment:

The unrealircd taball in the gentoo mirrors _is_ affected (
Unreal3.2.8.1.tar.gz ) but the Manifest file’s signatures match the
_unaffected_ tarball. This discrepancy is how the backdoor was discovered.

So, please just flush the tar.gz from gentoo’s mirrors, teach people to not
blindly run “ebuild *.ebuild manifest”, and unrealircd’s SRC_URI does not
include the current upstream tarball location:

SRC_URI=”http://www.unrealircd.com/downloads/${MY_P}.tar.gz“

(unrealircd’s mirror system was compromised by the attacker and so the tarball
is temporarily being hosted at the official site).

There’s a great deal of comment in the Talkback section of this post about how official repositories can be trusted. It appears that system broke down thoroughly in this case.

Every time I write about Windows security software, I get a predictable flood of responses from Linux advocates who claim that they don’t need any such protection. Today comes a shining example of why they’re wrong.

If you downloaded and installed the open-source Unreal IRC server in the last 8 months or so, you’ve been pwned. Here’s the official announcement:
(CLICK HEADLINE FOR THE REST.)
[Image: PancakeBunny.jpg] I have no idea what you're talking about so here's a bunny with a pancake on it's head
Website
Reply
ralgith Offline
Consigliere
*****
Family
Posts: 2,640
Threads: 122
Joined: Sep 2009
Reputation: 164
Mood: None
Share
Thanks Given0
Thanks Received4
  Favorite Quote: "I have imagination! So the voices in my head tell me, and the people I see back them up." - Snimm on the CBT Forums
  My Attitude: 

Simoleans: §1,027,209.46
Items: (View All Items)
#2
06-14-2010, 09:50 PM
0
Yup, saw that the other day. Everyone, no matter which OS needs Maleware protection. I run ClamAV for my Anti-Virus, and I love it. People who think an OS is foolproof are idiots. Just like people who think some firewalls are impenetrable are idiots. If a hacker wants in bad enough, not even the best mil-spec firewall will stop them.

Linux, Mac, and UNIX ARE usually more secure than Windows. Usually. But no one is perfect.
[Image: tExeLhI.gif]
Reply
« Next Oldest | Next Newest »


  • View a Printable Version
Forum Jump:


Users browsing this thread: 1 Guest(s)
    |
  • Twitchin Kitten
  • |
  • Return to Top
  • |
  • Lite (Archive) Mode
  • |
  • Mark all forums read
  • |
  • RSS Syndication
Current time: 07-16-2025, 09:16 AM Powered By MyBB, © 2002-2025 Twitchin Kitten (R).
TK Gang© theme designed by:Twitchin Kitten®
© 2005-2025 twitchinkitten.com®
All content on this site is property of TwitchinKitten.com® and it's members and owner. All content copyrighted to TwitchinKitten.com® it's members and owner, and legitimate contributors.
All work, words, images and likenesses on this site is subject to US Copyright and Trademark law. Anyone found to be using my name, my work or the work of the site's members without express written permission from me or the registered member will be prosecuted to the fullest extent of the law. You are NOT allowed to copy, reproduce, use, re-purpose, display or redistribute any part of this website for any reason whatsoever without express written permission by me.

Linear Mode
Threaded Mode